Best-av1-protect.info
Best-av1-protect.info is a browser hijacker promoting the rogue anti-spyware application Anti-virus-1 (also known as Antivirus 1). Due to trojan viruses infiltrating your system and modifying browser settings, your internet surfing becomes redirected to the Best-av1-protect.info domain. Here you are either bombarded by aggressive advertisement recommending purchase and download of Anti-virus-1, or a fake online scanner reports numerous counterfeit parasites on your system in order to scare you into purchasing and installing Anti-virus-1.
File System Modifications
- The following files were created in the system:
# File Name 1 %Documents and Settings%\All Users\Application Data\AV1 2 %Documents and Settings%\All Users\Application Data\AV1\AV1.cab 3 %Documents and Settings%\All Users\Application Data\AV1\av1.exe 4 %Documents and Settings%\All Users\Application Data\AV1\AV1i.exe 5 %Documents and Settings%\All Users\Application Data\AV1\AV1i2.exe 6 %Documents and Settings%\All Users\Application Data\AV1\QWProtect.dll 7 %Documents and Settings%\All Users\Application Data\AV1\svchost.exe 8 %Documents and Settings%\All Users\Desktop\Anti-virus-1.lnk 9 %Documents and Settings%\All Users\Start Menu\Programs\Anti-virus-1 10 %Documents and Settings%\All Users\Start Menu\Programs\Anti-virus-1\Anti-virus-1.lnk 11 %Documents and Settings%\All Users\Start Menu\Programs\Anti-virus-1\Uninstall.lnk
Registry Modifications
- The following newly produced Registry Values are:
HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AV1HKEY_CURRENT_USER\Software\AV1\AV1\{F275E931-AFEC-4f70-B0D4-CC2731B945E0}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{70FEAD04-A7FD-4B89-B814-8A8251C90EF7}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\AppID\QWProtect.DLLHKEY_CLASSES_ROOT\AppID\{29256442-2C14-48CA-B756-3EE0F8BDC774}HKEY_CLASSES_ROOT\CLSID\{70FEAD04-A7FD-4B89-B814-8A8251C90EF7}HKEY_CLASSES_ROOT\Interface\{051C9A06-FB08-486F-B09B-8B33B261637D}HKEY_CLASSES_ROOT\QWProtect.QWProtectBHOHKEY_CLASSES_ROOT\TypeLib\{512E801E-2F02-4ADE-ACAA-58F08A22B2F8}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Monitor calibration"
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.